Changelog

What is new in Inventoros

Every release, straight from GitHub. Follow along as Inventoros grows.

  1. Release v2.0.0

    October 6, 2026

    Inventoros 2.0.0

    Inventoros 2.0.0 expands the inventory core with shipping, payments, customer portals, approvals, scheduled reports, multi-organization memberships and a runtime plugin platform. This is the first release after 1.0.8.

    Upgrading from 1.0.x

    Upgrade manually once. The updater shipped in 1.0.8 and earlier cannot follow GitHub's release-download redirects. Back up your database and files, drain active work, and follow the upgrade guide. Clear old caches before migrating. PHP 8.4.1 or newer is required; PHP 8.4 and 8.5 are supported. The scheduler must run every minute.

    Other compatibility changes include snake_case MCP tool names, plugin assets moving to public/plugin-assets, bearer-token-only REST authentication and AGPL-3.0-only licensing. Releases through 1.0.8 remain MIT licensed.

    Highlights

    • Shipping and fulfilment with EasyPost or manual shipments, partial shipment support, tracking and shipment emails.
    • Customer portal, line/order discounts, payments, refunds, invoices and currency-aware receivables and analytics.
    • Optional approval workflows, scheduled cycle counts and report emails, expanded barcode scanning and warehouse access controls.
    • Organization memberships and switching, organization-bound API tokens and atomic inter-company stock transfers.
    • Signed plugin marketplace, runtime plugin pages/widgets/tabs, additional lifecycle hooks, plugin MCP tools and webhook events, and a documented core PHP extension API.
    • Production Docker image and a signed cPanel package with compiled assets, production Composer dependencies and a verified release manifest.

    Release audit fixes

    The release audit tightened tenant access to installation updates/backups, serialized stock-operation transitions, rechecked scheduled-report recipients at delivery, fixed queue reservation lifetimes, capped low-stock reports, improved update rollback behavior and persisted Docker plugins across services. It also fixed guest-member cycle counts, plugin query isolation and variant transfer webhook payloads. Vue, source-map-js and shell-quote security fixes are included.

    Downloads

    • cPanel/shared hosting: inventoros-cpanel-2.0.0.zip and its detached Ed25519 signature, inventoros-cpanel-2.0.0.zip.sig. Follow INSTALL.md inside the archive. No Node.js build is needed on the server.
    • Docker: ghcr.io/inventoros/inventoros:2.0.0, with Docker deployment instructions.
    • Example plugin: hello-world-plugin.zip. Prefer the signed marketplace copy when listed; manual ZIP uploads require INVENTOROS_ALLOW_PLUGIN_UPLOADS=true.

    Known limits and next work

    Stock reservations/available-to-promise are planned and are not included. Work orders currently support untracked, non-variant products; tracked products and virtual kits are refused to preserve inventory integrity. Inter-company transfers do not move batch/serial-tracked stock or kits.

    Organization membership administration screens and business-specific 3PL workflows remain plugin work. Some notification/assignee pickers still list home-organization users only. Large cycle-count performance, expired-export cleanup and the Tailwind 3 development dependency advisories remain follow-up work. Production npm and Composer dependency audits pass.

    See the full changelog and release audit for details and the prioritized backlog.

    View on GitHub
  2. Release v1.0.8

    August 2, 2026

    Inventoros v1.0.8

    cPanel Installation Package

    This release includes a pre-built package optimized for cPanel shared hosting.

    Download: inventoros-cpanel-1.0.8.zip

    See INSTALL.md inside the zip for installation instructions.

    What's Included

    • Pre-compiled frontend assets (no npm required on server)
    • Production-optimized Composer dependencies
    • cPanel-compatible directory structure
    • Modified index.php for split directory setup
    View on GitHub
  3. Release v1.0.7

    August 2, 2026

    Inventoros v1.0.7

    cPanel Installation Package

    This release includes a pre-built package optimized for cPanel shared hosting.

    Download: inventoros-cpanel-1.0.7.zip

    See INSTALL.md inside the zip for installation instructions.

    What's Included

    • Pre-compiled frontend assets (no npm required on server)
    • Production-optimized Composer dependencies
    • cPanel-compatible directory structure
    • Modified index.php for split directory setup
    View on GitHub
  4. Release v1.0.6

    July 22, 2026

    Inventoros v1.0.6

    cPanel Installation Package

    This release includes a pre-built package optimized for cPanel shared hosting.

    Download: inventoros-cpanel-1.0.6.zip

    See INSTALL.md inside the zip for installation instructions.

    What's Included

    • Pre-compiled frontend assets (no npm required on server)
    • Production-optimized Composer dependencies
    • cPanel-compatible directory structure
    • Modified index.php for split directory setup
    View on GitHub
  5. Release v1.0.5

    July 22, 2026

    Inventoros v1.0.5

    cPanel Installation Package

    This release includes a pre-built package optimized for cPanel shared hosting.

    Download: inventoros-cpanel-1.0.5.zip

    See INSTALL.md inside the zip for installation instructions.

    What's Included

    • Pre-compiled frontend assets (no npm required on server)
    • Production-optimized Composer dependencies
    • cPanel-compatible directory structure
    • Modified index.php for split directory setup
    View on GitHub
  6. Release v1.0.4

    July 22, 2026

    Inventoros v1.0.4

    cPanel Installation Package

    This release includes a pre-built package optimized for cPanel shared hosting.

    Download: inventoros-cpanel-1.0.4.zip

    See INSTALL.md inside the zip for installation instructions.

    What's Included

    • Pre-compiled frontend assets (no npm required on server)
    • Production-optimized Composer dependencies
    • cPanel-compatible directory structure
    • Modified index.php for split directory setup
    View on GitHub
  7. Release v1.0.3

    June 5, 2026

    Inventoros v1.0.3 — Security & Reliability

    Implements every actionable finding from the 2026-06-03 security + reliability audit, each with regression tests. Full test suite green (1255 tests); cPanel package is now signed.

    Security

    • Plugin slug path containment (reject traversal/separators + realpath-contained deletes)
    • GraphQL category/location references scoped to the caller's organization (IDOR)
    • Update-availability check requires admin; backup filenames validated against an allowlist + the known-backup set
    • GraphQL free-text length caps to match REST
    • SSRF guard fails closed on empty DNS in production
    • Nonce-based Content-Security-Policy (Vite + Ziggy nonce, vue-i18n JIT); deprecated X-XSS-Protection removed
    • Plugin manifest guard + a startup warning when uploads are enabled without signature verification

    Reliability / data integrity

    • Shared, locked cancel-restock across web/REST/GraphQL (GraphQL no longer leaks stock on cancel)
    • Transactions + row locks + status re-checks on PO receiving, work-order complete/cancel, stock-audit complete, web order cancel, and return receive
    • Org-scoped, fail-fast product lookup in web order updates
    • Stock notifications deferred until after the locked transaction commits
    • All advertised webhook events now actually dispatch (stock, order, and purchase-order lifecycle)
    • In-app updater auto-restores from backup if file replacement fails
    • Product imports retry transient failures and keep the upload until the final attempt

    Signed updates

    Release archives are now signed with a detached Ed25519 signature (inventoros-cpanel-1.0.3.zip.sig). The in-app updater verifies the archive against the public key shipped in .env.example before extracting. Set INVENTOROS_UPDATE_PUBLIC_KEY (already in .env.example); to install unsigned builds set INVENTOROS_UPDATE_SIGNATURE_REQUIRED=false.

    Known limitation

    Stock transfers between locations remain a no-op audit record (global stock model); per-location stock tracking is a future change.

    See INSTALL.md inside the zip for cPanel installation steps.

    View on GitHub
  8. Release v1.0.2

    April 6, 2026

    Inventoros v1.0.2

    cPanel Installation Package

    This release includes a pre-built package optimized for cPanel shared hosting.

    Download: inventoros-cpanel-1.0.2.zip

    See INSTALL.md inside the zip for installation instructions.

    What's Included

    • Pre-compiled frontend assets (no npm required on server)
    • Production-optimized Composer dependencies
    • cPanel-compatible directory structure
    • Modified index.php for split directory setup
    View on GitHub
  9. Release v1.0.1B-CPANEL

    December 22, 2025

    Inventoros v1.0.1B-CPANEL

    cPanel Installation Package

    This release includes a pre-built package optimized for cPanel shared hosting.

    Download: inventoros-cpanel-1.0.1B-CPANEL.zip

    See INSTALL.md inside the zip for installation instructions.

    What's Included

    • Pre-compiled frontend assets (no npm required on server)
    • Production-optimized Composer dependencies
    • cPanel-compatible directory structure
    • Modified index.php for split directory setup
    View on GitHub
  10. Release v1.0.0B-CPANEL-B

    December 14, 2025

    Inventoros v1.0.0B-CPANEL-B

    cPanel Installation Package

    This release includes a pre-built package optimized for cPanel shared hosting.

    Download: inventoros-cpanel-1.0.0B-CPANEL-B.zip

    See INSTALL.md inside the zip for installation instructions.

    What's Included

    • Pre-compiled frontend assets (no npm required on server)
    • Production-optimized Composer dependencies
    • cPanel-compatible directory structure
    • Modified index.php for split directory setup
    View on GitHub
  11. Version 1.0BETA

    October 14, 2025

    We’re officially launching Inventoros v1.0BETA — our first public milestone in reshaping the open-source inventory and warehouse management landscape.

    ⚠️ Active Development Disclaimer: Inventoros is still in early-stage development. Core features are functional, but APIs, UI flows, and plugin behavior remain fluid as we stabilize for production readiness. Early adopters and contributors are encouraged to jump in, test, and provide feedback as we harden the platform.

    Vision: To democratize warehouse and inventory management by giving small and medium-sized businesses enterprise-grade power wrapped in a developer-friendly, extensible framework.

    Highlights in 1.0BETA

    ✅ Full CRUD product & order management with auto-inventory sync

    ✅ Role-based access control and multi-user architecture

    ✅ Plugin-ready system with hooks and filters

    ✅ Installer wizard with environment validation

    ✅ Multi-currency and responsive dark-mode UI

    🚧 CSV import/export and analytics dashboards in active development

    Stack: Laravel 12 · Inertia.js · Vue 3 · Vite · MySQL

    View on GitHub

Run the latest Inventoros

Updating is straightforward. The docs walk you through upgrades and backups.